X-Git-Url: https://git.openstreetmap.org./chef.git/blobdiff_plain/b6b95dafa71524e7baa9614e09f7a7e2d5e1206c..49cdf148a0562915edfd17e9b4ab19c9cd7aa721:/cookbooks/community/recipes/default.rb diff --git a/cookbooks/community/recipes/default.rb b/cookbooks/community/recipes/default.rb index 5ad6e7afb..89743de31 100644 --- a/cookbooks/community/recipes/default.rb +++ b/cookbooks/community/recipes/default.rb @@ -17,35 +17,14 @@ # limitations under the License. # +include_recipe "accounts" include_recipe "docker" +include_recipe "geoipupdate" include_recipe "git" include_recipe "ssl" -ssl_certificate "community.openstreetmap.org" do - domains ["community.openstreetmap.org", "community.osm.org"] -end - -# passwords = data_bag_item("community", "passwords") - -# postgresql_user "community_user" do -# cluster node[:db][:cluster] -# password passwords["database"] -# end - -# postgresql_database "community_db" do -# cluster node[:db][:cluster] -# owner "community_user" -# end - -# postgresql_extension "hstore" do -# cluster node[:db][:cluster] -# database "community_db" -# end - -# postgresql_extension "pg_trgm" do -# cluster node[:db][:cluster] -# database "community_db" -# end +passwords = data_bag_item("community", "passwords") +license_keys = data_bag_item("geoipupdate", "license-keys") unless kitchen? directory "/srv/community.openstreetmap.org" do owner "root" @@ -62,13 +41,109 @@ end git "/srv/community.openstreetmap.org/docker" do action :sync repository "https://github.com/discourse/discourse_docker.git" - revision "master" + revision "main" depth 1 user "root" group "root" + notifies :run, "execute[discourse_container_data_rebuild]" + notifies :run, "execute[discourse_container_web_only_bootstrap]" + notifies :run, "execute[discourse_container_mail_receiver_rebuild]" +end + +template "/srv/community.openstreetmap.org/docker/containers/data.yml" do + source "data.yml.erb" + owner "root" + group "root" + mode "644" + variables :passwords => passwords + notifies :run, "execute[discourse_container_data_rebuild]" +end + +template "/srv/community.openstreetmap.org/docker/containers/web_only.yml" do + source "web_only.yml.erb" + owner "root" + group "root" + mode "644" + variables :license_keys => license_keys, :passwords => passwords + notifies :run, "execute[discourse_container_web_only_bootstrap]" +end + +template "/srv/community.openstreetmap.org/docker/containers/mail-receiver.yml" do + source "mail-receiver.yml.erb" + owner "root" + group "root" + mode "644" + variables :passwords => passwords + notifies :run, "execute[discourse_container_mail_receiver_rebuild]" +end + +# Destroy Bootstap Start +execute "discourse_container_data_rebuild" do + action :nothing + command "./launcher rebuild data" + cwd "/srv/community.openstreetmap.org/docker/" + user "root" + group "root" +end + +ssl_certificate "community.openstreetmap.org" do + domains ["community.openstreetmap.org", "community.osm.org", "communities.openstreetmap.org", "communities.osm.org"] + notifies :run, "execute[discourse_container_web_only_bootstrap]" +end + +execute "discourse_container_data_start" do + action :run + command "./launcher start data" + cwd "/srv/community.openstreetmap.org/docker/" + user "root" + group "root" +end + +execute "discourse_container_web_only_bootstrap" do + action :nothing + command "./launcher bootstrap web_only" + cwd "/srv/community.openstreetmap.org/docker/" + user "root" + group "root" + notifies :run, "execute[discourse_container_web_only_destroy]", :immediately +end + +execute "discourse_container_web_only_destroy" do + action :nothing + command "./launcher destroy web_only" + cwd "/srv/community.openstreetmap.org/docker/" + user "root" + group "root" + notifies :run, "execute[discourse_container_web_only_start]", :immediately +end + +execute "discourse_container_web_only_start" do + action :run + command "./launcher start web_only" + cwd "/srv/community.openstreetmap.org/docker/" + user "root" + group "root" + notifies :run, "execute[discourse_container_data_start]", :before +end + +# Destroy Bootstap Start +execute "discourse_container_mail_receiver_rebuild" do + action :nothing + command "./launcher rebuild mail-receiver" + cwd "/srv/community.openstreetmap.org/docker/" + user "root" + group "root" +end + +template "/etc/cron.daily/community-backup" do + source "backup.cron.erb" + owner "root" + group "root" + mode "750" end -# TBC: discourse docker templates -# web.ssl.template.yml -# redis.template.yml -# TBC: discourse launcher rebuild +node.default[:prometheus][:exporters][443] = { + :name => "community", + :address => "#{node[:prometheus][:address]}:443", + :sni => "community.openstreetmap.org" +}